Summary
Togoder Security scanned the npm package @safe-global/safe-gateway-typescript-sdk@3.23.1 on Oct 4, 2026. An AI review of 22 source files produced 2 medium, 1 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 3
Potential SSRF / unrestricted URL fetching
NPS-2856B6279CAF
fetchData and getData accept arbitrary urls and perform fetch calls, potentially allowing requests to internal services if the url is attacker-controlled.
Credential forwarding
NPS-5299A224E786
credentials parameter is passed directly to fetch options, which may include cookies/auth headers for cross-origin requests; no validation on target origin.
Dynamic RegExp construction
NPS-60E0F5D0F92E
replaceParam builds a RegExp from a key parameter without escaping, which could cause errors or regex injection if keys contain special characters.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| dist/utils.js | medium | The utility functions appear benign but allow arbitrary network requests and credential forwarding, with minor regex handling concerns; no malicious patterns such as exfiltration or code execution were found. |
| dist/config.js | safe | No malicious patterns detected |
| dist/endpoint.js | safe | No malicious patterns detected; the code implements straightforward HTTP endpoint wrappers using utility functions with no signs of exfiltration, credential harvesting, obfuscation, or process spawning. |
| dist/index.js | safe | No malicious patterns detected; the code is a legitimate Safe API client with standard HTTP endpoint wrappers. |
| dist/types/accounts.js | safe | No malicious patterns detected |
| dist/types/api.js | safe | No malicious patterns detected |
| dist/types/auth.js | safe | The file contains only standard TypeScript/JavaScript export boilerplate and a source map reference with no executable or malicious logic. |
| dist/types/chains.js | safe | No malicious patterns detected; the file only defines TypeScript enums for RPC authentication, gas price types, and feature flags with no executable or network-related code. |
| dist/types/common.js | safe | No malicious patterns detected |
| dist/types/contracts.js | safe | No malicious patterns detected |
| dist/types/decoded-data.js | safe | No malicious patterns detected |
| dist/types/delegates.js | safe | No malicious patterns detected |
| dist/types/emails.js | safe | No malicious patterns detected |
| dist/types/human-description.js | safe | No malicious patterns detected |
| dist/types/master-copies.js | safe | The file contains only standard TypeScript/JavaScript module boilerplate and a source map reference, with no malicious patterns detected. |
| dist/types/notifications.js | safe | No malicious patterns detected |
| dist/types/recovery.js | safe | No malicious patterns detected |
| dist/types/relay.js | safe | No malicious patterns detected |
| dist/types/safe-apps.js | safe | No malicious patterns detected |
| dist/types/safe-info.js | safe | No malicious patterns detected |
| dist/types/safe-messages.js | safe | No malicious patterns detected |
| dist/types/transactions.js | safe | No malicious patterns detected |
Scanned versions of @safe-global/safe-gateway-typescript-sdk
| Version | Verdict | Files | Scanned |
|---|---|---|---|
| 3.23.1 | Needs review | 22 | Oct 4, 2026 |
Frequently asked questions
Is @safe-global/safe-gateway-typescript-sdk safe to use?
No confirmed malware was found in @safe-global/safe-gateway-typescript-sdk@3.23.1, but the review flagged 2 medium, 1 low severity findings for risky patterns worth checking before you rely on it.
Does @safe-global/safe-gateway-typescript-sdk contain malware?
No malware was identified in @safe-global/safe-gateway-typescript-sdk@3.23.1 when Togoder Security scanned it on Oct 4, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was @safe-global/safe-gateway-typescript-sdk checked?
Togoder Security downloaded the published npm package and had an AI model read its 22 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan @safe-global/safe-gateway-typescript-sdk together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in @safe-global/safe-gateway-typescript-sdk@3.23.1, cost nothing.